Posted by SillyOldDuffer on 03/11/2022 16:43:15:
The main problem with email for Two Factor Authentication is it's not immediate. Too many people check their email once a day or less which is too slow for an authentication check intended to speed valid transactions through the system.
… but, if they're sitting (as they would be) at their computer, trying to log on to online banking and the bank wants to do a 2FA, they'd certainly have pretty much instant access to an email that they are aware has been sent. It's not a "check once a day" case, it's check on demand (in my case all emails come direct to my machine – I don't have to go looking for them).
With only a landline, doing the second factor by phone is actually more problematic since it could be answered by someone else on another extension. And if that someone else has cognitive problems, you've probably missed the auth-no and have to start again (if the bank lets you).
Perhaps better for the blind/visually-impaired. Worse for the hearing impaired.
Frankly, I'd like to see the bank quantify the email vs phone security risks rather just parading out the "email is insecure" knee-jerking.
Edited By Peter Greene 🇨🇦 on 03/11/2022 17:54:21